PROVABLE AI GOVERNANCE
Source code, customer records, production credentials — leaving every day through browsers and coding agents.
no account needed to verify · no deck on the call
BUILT FOR SECURITY AND PLATFORM TEAMS
why nothing has caught this yet
Inspection happens before encryption, on the device — the only place the content still exists in the clear.
what it governs
Inspects prompts before they leave the tab on ChatGPT, Claude, Gemini and Perplexity. Redact, warn or block, with the reason shown to the person typing. 30-second install, or pushed silently through Intune, JAMF or Chrome Enterprise.
A gateway between Claude Code, Cursor and any MCP server, with Codex governed through agent hooks instead. One command routes the clients already configured on the machine through it. Policy applies to every tool call, and a blocked call returns a readable reason, not a silent failure.
Read-only OAuth into Google Workspace or Microsoft 365 shows every AI app your staff already authorized, with nothing installed anywhere. This is the five-minute version, and where most teams start.


and when someone asks what happened
Every event a device can sign is signed on that device; where a browser cannot, it is recorded as unsigned rather than counted as proven. Signatures fold into one root per day, each sealed to the day before, published as a signed checkpoint whose key resolves from a public JWKS. Your auditor re-derives all of it offline.
eight signed events shown · alter any one and every hash above it changes
Click any row to change what it says, the way a vendor could.
Every row folds into the fingerprint beneath it. Change one and the seal breaks — the same check an auditor runs, computed here in your browser with nothing leaving the page.
Altering a record from six weeks ago means re-signing every day since — and the day after that, and the day after that.


Want to see this running against your own AI traffic?
Deterministic patterns are the only thing allowed to stand between an engineer and their work. The model-based layers rank and explain; they never silently stop a request. Most vendors describe three detection layers and imply all three enforce — this is the sentence that says which one does.


A signed record proves what we saw. It says nothing about the laptop that routed around us. So each machine signs what it was governing — which agents were hooked, which servers wrapped — checked against the key registered to that device and folded into the same daily root. A gap stops being an assumption and becomes evidence.


A signed root is only as good as your ability to prove we did not re-sign it later. So publish it outside our blast radius: an S3 bucket with Object Lock, or a witness repository that commits each day’s root on a schedule you control. The bundle ships the witness config; nothing about this needs our cooperation after setup.
On a hosted deployment the log-signing key is ours — so this, not key custody, is what makes the record independent of us.
what a security review will ask
AES-256-GCM at rest, TLS 1.2+ in transit. Pre-SOC 2.
Every other AI-governance vendor in this category quotes on request, every tier of it. Three of ours are on this page and you can read them without talking to anybody. Enterprise is the exception, and we would rather say so up here than have you find it at the bottom of a card: what it costs turns on headcount, on where it runs and on what we have to sign, so we scope it with you instead of printing a number that would be wrong for most of the organisations reading this. The free tier is a pilot for one team, not a plan for your company — ten people is enough to point Vloex at real traffic and see what comes back, and we would rather say so here than have you find out on your eleventh invite.
Setting Vloex up means connecting a workspace and deciding what to enforce — an admin’s job, and a short conversation. That is why the button above is a call and not a signup.
questions people actually ask
Those tools were built for files and web traffic, not prompts. They see an encrypted session to an AI provider and cannot read what is inside it, cannot tell a corporate account from a personal one, and cannot coach the person in the moment. Vloex inspects on the device, before encryption, which is the only place the content still exists in the clear.
On the gateway path scanning and policy run on your machine, so a blocked call never leaves it. What we receive for a call that proceeds is event metadata, its signature, and the text of the call — the tool arguments up to 50,000 characters and the result up to 200,000, which are the backend’s per-field limits — stored encrypted. Anything past those limits is cut, and the event records that it was cut rather than letting the shortfall pass for a complete record. This is the full payload, not a preview: the ledger is re-scanned from the text it receives, so text that never arrives is text nothing ever checked. The browser extension sends the prompt to be scanned before the request goes out, and what it then stores is governed by your coverage level — up to 50,000 characters each of prompt and response at full trace, none of either at metadata-only. If that is still too much, the entire platform can run self-hosted inside your environment.
No. Connect Google Workspace or Microsoft 365 with read-only OAuth and you will see every AI app your team has authorized within a few minutes. The extension and the gateway are how you move from seeing to stopping, and you can add them later.
Policy decisions run inside a 250ms interceptor budget (server p95 under 150ms), and blocked agent calls return a readable reason instead of a failure, so the agent can correct itself and continue. Only the deterministic layer blocks; model-based layers advise and prioritize review rather than silently stopping work.
Thirty minutes, no deck. We connect your workspace live, look at what turns up, and if it is not a fit we will say so on the call rather than send you a sequence of follow-up emails.
design partners
A small number of design partners this quarter. The full platform at no cost, an hour of setup with the people who built it, and a weekly loop where what you say changes what gets built. In exchange we ask for real usage and permission to name you later.